Associated Malware Groups
The filename is associated with the malware groups:
- System Back Door
- Cloaked Malware
File Behavior
ECJEW .EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Writes to another Process's Virtual Memory (Process Hijacking)
- This Process Deletes Other Processes From Disk
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Executes a Process
- Creates a TCP port which listens and is available for communication initiated by other computers
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- Terminates Processes
- Can communicate with other computer systems using HTTP protocols
- Registers a Dynamic Link Library File
- Copies files
- Creates a new Background Service on the machine
- Injects code into other processes
ECJEW .EXE has been the subject of the following behavior:
- Executed as a Process
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Copied to multiple locations on the system
Country Of Origin
The filename ECJEW .EXE was first seen on Feb 7 2010 in the following geographical regions of the Prevx community:
- Serbia on Feb 7 2010
- Malaysia on Feb 7 2010
- Turkey on Feb 7 2010
File Name Aliases
ECJEW .EXE can also use the following file names:
- LSASS.EXE
- ECJEW.EXE
- 15208234.EXE
Filesizes
The following file size has been seen:
- 23,552 bytes
- 44,032 bytes
File Type
The filename ECJEW .EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.